Discussion:
Changing Syslog facility
Marcus Inskip
2014-09-19 15:14:44 UTC
Permalink
Hi,

I’m trying to change the logging facility of audispd to local2 to send logs off to a remote server via Rsyslog without logging twice is this possible?

Many thanks in advance,

Marcus
Marcus Inskip
2014-09-19 15:25:56 UTC
Permalink
Apologies:

O/S: Redhat 6.5
Rsyslog: 5.8.10-8
AuditD: 2.2-2
Hi,
I’m trying to change the logging facility of audispd to local2 to send logs off to a remote server via Rsyslog without logging twice is this possible?
Many thanks in advance,
Marcus
--
Linux-audit mailing list
https://www.redhat.com/mailman/listinfo/linux-audit
Steve Grubb
2014-09-19 15:39:12 UTC
Permalink
Post by Marcus Inskip
I’m trying to change the logging facility of audispd to local2 to send logs
off to a remote server via Rsyslog without logging twice is this possible?
The audisp-syslog plugin should do it. Just open
/etc/audisp/plugins.d/syslog.conf and add LOCAL2 to the args line. Then enable
the module and restart the audit daemon.

-Steve

Continue reading on narkive:
Loading...